CoSMed: a confidentiality-verified social media platform

Bauereiß, Thomas, Pesenti Gritti, Armando, Popescu, Andrei and Raimondi, Franco ORCID: https://orcid.org/0000-0002-9508-7713 (2018) CoSMed: a confidentiality-verified social media platform. Journal of Automated Reasoning, 61 (1-4) . pp. 113-119. ISSN 0168-7433 [Article] (doi:10.1007/s10817-017-9443-3)

[img]
Preview
PDF - Final accepted version (with author's formatting)
Download (238kB) | Preview

Abstract

This paper describes progress with our agenda of formal verification of information flow security for realistic systems. We present CoSMed, a social media platform with verified document confidentiality. The system’s kernel is implemented and verified in the proof assistant Isabelle/HOL. For verification, we employ the framework of Bounded-De- ducibility (BD) Security, previously introduced for the conference system CoCon. CoSMed is a second major case study in this framework. For CoSMed, the static topology of declas- sification bounds and triggers that characterized previous instances of BD Security has to give way to a dynamic integration of the triggers as part of the bounds. We also show that, from a theoretical viewpoint, the removal of triggers from the notion of BD Security does not restrict its expressiveness.

Item Type: Article
Additional Information: Special Issue: Milestones in Interactive Theorem Proving
Research Areas: A. > School of Science and Technology > Computer Science > Foundations of Computing group
Item ID: 23357
Notes on copyright: This is a post-peer-review, pre-copyedit version of an article published in Journal of Automated Reasoning. The final authenticated version is available online at: http://dx.doi.org/10.1007/s10817-017-9443-3
Useful Links:
Depositing User: Andrei Popescu
Date Deposited: 19 Jan 2018 16:00
Last Modified: 17 Jun 2021 13:24
URI: https://eprints.mdx.ac.uk/id/eprint/23357

Actions (login required)

View Item View Item

Statistics

Downloads
Activity Overview
170Downloads
360Hits

Additional statistics are available via IRStats2.